Skip to content

Latest commit

Β 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ SOC Home Lab Environment

A personal Security Operations Center (SOC) lab environment built for hands-on blue team training, threat detection, and DFIR practice. This project documents my journey in building a segmented network with enterprise-grade security monitoring capabilities on a home lab budget.

πŸ“‹ Table of Contents

Overview

This home lab simulates a small enterprise network with proper segmentation, traffic monitoring, and log analysis capabilities. The primary goal is to develop practical SOC analyst skills through:

  • Real-time network traffic analysis
  • Log aggregation and SIEM operations
  • Intrusion detection and alerting
  • Digital forensics and incident response (DFIR) practice

Architecture

Network Topology

The environment follows a defense-in-depth approach with network segmentation enforced at the firewall level.

Traffic Flow

ISP Router
    β”‚
    β–Ό (WAN)
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   pfSense Firewall              β”‚
β”‚   Zeek + Suricata (IDS/NSM)     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
    β”‚ (LAN - Trunk)
    β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚      TP-Link TL-SG105E          β”‚
β”‚       (Managed Switch)          β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚    VLAN 10     β”‚    VLAN 20     β”‚
β”‚  Users Network β”‚ Servers Networkβ”‚
β”‚  10.10.10.0/24 β”‚192.168.10.0/24 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                        β”‚
                        β–Ό
              β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
              β”‚ Proxmox Server  β”‚
              β”‚192.168.10.x     β”‚
              β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
              β”‚ VMs:            β”‚
              β”‚ β€’ Arch Server   β”‚
              β”‚ β€’ Security Onionβ”‚
              β”‚ β€’ Splunk        β”‚
              β”‚ β€’ Kali Linux    β”‚
              β”‚ β€’ Arch HTB      β”‚
              β”‚ β€’ Win11         β”‚
              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Hardware Specifications

Proxmox Virtualization Host

Component Specification
CPU Intel Core i5-12500 (12 cores)
RAM 32 GB DDR4
Storage 1 TB NVMe SSD + 1 TB HDD
GPU Integrated (APU)

Network Infrastructure

Device Model Role
Firewall Repurposed Laptop pfSense + Zeek + Suricata
Switch TP-Link TL-SG105E VLAN Management (5 ports)

Network Design

VLAN Segmentation

VLAN ID Name Subnet Purpose Switch Ports
10 Users 10.10.10.0/24 Personal devices, isolated from servers 2
20 Servers 192.168.10.0/24 Lab VMs, security tools, Proxmox 2

Firewall Rules Philosophy

  • Users VLAN β†’ Servers VLAN: Blocked by default
  • Servers VLAN β†’ Users VLAN: Blocked by default
  • Inter-VLAN routing: Denied unless explicitly required
  • Outbound: Allowed with logging for analysis

This segmentation ensures that even if a device on the Users network is compromised, lateral movement to the lab environment is prevented.

Security Stack

Virtual Machines (Proxmox)

VM OS Purpose Status
Arch Server Arch Linux + Docker CyberChef, n8n, core services Always On
Security Onion Security Onion Network security monitoring (Standalone) On-demand
Splunk Debian SIEM, log aggregation, alerting On-demand
HTB-Arch Arch Linux (Custom) HackTheBox Sherlock challenges, DFIR On-demand
Kali Linux Kali Penetration testing, red team simulations On-demand
Win11-Lab Windows 11 Malware analysis, Windows forensics On-demand

Docker Containers (Arch Server)

Container Purpose
CyberChef Data encoding/decoding, analysis
n8n Workflow automation, future LLM integration

Monitoring Pipeline

Network Traffic
      β”‚
      β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚           pfSense Firewall          β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚    Zeek     β”‚  β”‚   Suricata   β”‚  β”‚
β”‚  β”‚ (Metadata)  β”‚  β”‚   (IDS/IPS)  β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
          β”‚                β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                  β–Ό
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚   Splunk   β”‚
           β”‚   (SIEM)   β”‚
           β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜
                 β”‚ (Planned)
                 β–Ό
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚    n8n     β”‚
           β”‚ + LLM API  β”‚
           β”‚(Automation)β”‚
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Log Sources:

  • Zeek connection logs, DNS, HTTP, SSL metadata
  • Suricata alerts (ET Open ruleset)
  • pfSense firewall logs

Use Cases & Projects

HackTheBox Sherlock Challenges

Completed DFIR challenges using this lab environment:

Challenge Category Skills Practiced
Brutus Auth Log Analysis Linux authentication forensics
Meerkat Network Analysis PCAP analysis, C2 detection
Unit42 Malware Analysis Static/dynamic analysis
PhishNet Email Forensics Phishing email analysis, IOC extraction
Campfire-1 Windows Forensics Event log analysis

πŸ“ Writeups available in my DFIR-Writeups repository

Detection Validation

  • Verified Security Onion detection capabilities using Nmap scans from Users VLAN
  • Tested alert generation for reconnaissance activities

Challenges & Solutions

USB 2.0 Ethernet Adapter Latency

Problem: The laptop repurposed as a pfSense firewall lacks USB 3.0 ports. The external USB Ethernet adapter (required for WAN connection) operates on USB 2.0, causing intermittent connectivity issues and latency spikes.

Impact:

  • Occasional packet loss during high-throughput scenarios
  • Zeek/Suricata may miss packets during traffic bursts

Current Workaround:

  • Monitoring for connection drops
  • Considering dedicated low-power hardware (e.g., Protectli Vault, used Dell OptiPlex) for future upgrade

Lessons Learned:

  • Hardware limitations matter in network security
  • USB Ethernet adapters are not ideal for firewall deployments
  • Plan hardware requirements before building the lab

Future Improvements

  • Replace pfSense laptop with dedicated mini PC
  • Add dedicated SPAN port for Security Onion
  • Implement Wazuh for endpoint detection (EDR)
  • LLM-powered log analysis β€” Integrate local LLM with n8n for automated log summarization, anomaly detection, and server health monitoring
  • Create attack simulations with Atomic Red Team
  • Add Velociraptor for endpoint forensics
  • Document more HackTheBox Sherlock writeups

Repository Structure

homelab-soc-environment/
β”œβ”€β”€ diagrams/
β”‚   └── network-topology.png
└── configurations/
    β”œβ”€β”€ pfsense-firewall-rules.md
    └── vlan-setup.md

Skills Demonstrated

  • Network segmentation and VLAN configuration
  • Firewall rule design and implementation
  • IDS/IPS deployment (Suricata)
  • Network Security Monitoring (Zeek)
  • SIEM administration (Splunk)
  • Virtualization (Proxmox)
  • Digital Forensics and Incident Response (DFIR)

Connect


This project is part of my journey to becoming a SOC Analyst. Feedback and suggestions are welcome!

About

Enterprise-simulated home lab with pfSense, Zeek, Suricata, and Splunk. Network security monitoring playground.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors